Definition:
Phishing is a social engineering attack in which a person or group impersonates a trusted entity to induce someone to disclose information, authorize a transaction, or perform a harmful action. It may seek credentials, personal data, authentication codes, payments, or the installation of malicious software.
The deception can arrive through email, SMS, calls, messaging services, social networks, advertisements, QR codes, or pages that imitate legitimate services. The common element is not the channel but the combination of impersonation and persuasion used to make the target act.
A phishing attack does not always install malware. Many attempts lead to fake forms, request a transfer, or persuade a user to approve access. Not every unsolicited message is phishing either: spam describes unsolicited mass distribution, whereas phishing adds a fraudulent purpose based on deception.
Table of contents
How a phishing attack works
The attacker constructs a pretext that makes the request appear plausible. It may imitate a bank alert, invoice, sign-in notice, delivery update, internal communication, or support message. In targeted campaigns, information about the organization, role, or relationships of the recipient is used to adapt the content.
Impersonation may rely on falsified sender names, visually similar domains, compromised accounts, or sites that reproduce a brand’s appearance. A URL may change one character, use another subdomain, or be hidden behind a button. HTTPS and the browser padlock confirm an encrypted connection to the displayed domain; they do not prove that the domain belongs to the entity it claims to represent.
The message attempts to provoke an action before the recipient verifies its origin. It may direct the person to a fake sign-in page, ask them to open a file, scan a QR code, provide a one-time code, or change payment details. Some intermediary pages relay the sign-in to the real service so that credentials and codes can be captured while they are still valid.
The consequences depend on the action obtained. They include account takeover, financial fraud, access to corporate systems, data exposure, and the distribution of malware or ransomware. A compromised account can also be used to send new messages from a familiar identity.
Forms of phishing
The names usually describe the channel or level of personalization. The main forms include:
- Email phishing: messages imitate commercial, administrative, or internal communications. They may be distributed widely or segmented by organization.
- Spear phishing and whaling: spear phishing targets specific people with an adapted pretext. Whaling refers to attacks aimed at executives or other profiles with decision-making authority.
- Smishing: SMS or other mobile messages lead to a fake website, request information, or induce a phone call.
- Vishing: calls or voice messages are used for deception. Caller ID spoofing and synthetic voices or deepfakes can reinforce the impersonation, but the request still needs independent verification.
- QR code phishing: the destination is hidden in a code normally opened from a mobile device, where checking the domain before proceeding may be more difficult.
- Messaging and social media phishing: fake profiles, conversations, or advertisements start the interaction and may exploit a legitimate account that was previously compromised.
Pharming is related but not identical. It manipulates DNS resolution, a hosts file, or another component to redirect traffic to a fraudulent destination, even when no persuasive message is involved.
Warning signs and verification
No single sign proves that a message is fraudulent. The sender, destination, request, and context need to be considered together. These signs justify additional verification:
- The sender or link domain does not exactly match the expected service.
- The message uses urgency, threats, secrecy, or a reward to discourage verification.
- It requests credentials, authentication codes, bank details, payments, or unusual account changes.
- An unexpected file, link, or QR code appears, even when the sender’s name is familiar.
- The communication contradicts the organization’s normal process or arrives through an unusual channel.
- The message includes some accurate information but requests an action that does not fit the conversation or service.
Correct spelling does not make a message legitimate. Campaigns can copy genuine communications, use machine translation, or generate polished text. A request should be checked by opening the service from its application, a bookmark, or a known address, or by contacting the entity through a number obtained from an independent source. The link, phone number, or contact details inside the suspicious message should not be used for that verification.
Prevention and response
Prevention combines user decisions and technical controls. Email and web filters can block known campaigns. SPF, DKIM, and DMARC help authenticate certain uses of a domain and reduce some forms of spoofing, but they do not stop messages sent from compromised accounts or lookalike domains.
Multi-factor authentication limits some of the damage when a password is stolen, although codes and approval prompts can also be targeted. Phishing-resistant methods bind authentication to the legitimate domain and provide stronger protection against intermediary pages. Within an organization, these controls are complemented by least-privilege access, simple reporting channels, and verification procedures for payments or sensitive changes.
A suspicious message should be reported through the provider’s or organization’s designated channel and deleted after retaining any information needed for investigation. FTC guidance on protection from phishing scams provides further identification and response guidance.
If credentials have been disclosed, they should be changed from a trusted device and legitimate address, active sessions should be closed, and recovery methods should be reviewed. When financial details have been shared or a payment authorized, the relevant institution needs to be contacted. If a suspicious file or program has been executed on a corporate device, it should be isolated according to the organization’s procedure and reported to the responsible team.
Phishing is identified through the relationship between the identity claimed by the message, the actual destination, and the requested action. Checking those three elements distinguishes it from legitimate communication, spam without a fraudulent purpose, and attacks that do not depend on persuasion.
